General educational information and FAIRE’s interpretation of the linked sources. This is not legal, clinical or regulatory advice. Read the disclaimer.
A risk-based law
The EU AI Act is the European Union's framework for regulating artificial intelligence according to the level of risk it may create. Not every AI system is treated the same way: the obligations can depend on what the system does and how it is used.
Healthcare can involve higher-risk uses because an AI output may influence access to services, a professional decision, a record or a person's wellbeing. The legal position depends on the specific system and circumstances, so this article is general information rather than legal advice.
Why intended purpose matters
An AI tool used to draft an administrative email is not the same use case as a system intended to support a clinical decision. Summarising information, generating a patient-facing document and supporting clinical judgement can each raise different questions about accuracy, oversight, transparency and documentation.
The product name alone does not answer those questions. Organisations need to understand what a system is designed to do, what they are asking it to do and where people remain responsible.
What should a practice do now?
- 01Know what AI tools are being used.
- 02Know what they are being used for.
- 03Identify who is responsible for each use.
- 04Consider whether the use is administrative or clinically significant.
- 05Review the tool before introducing it into an important workflow.
Application dates and AI literacy
The Commission’s current implementation timeline records initial provisions, including AI literacy and prohibited practices, applying from 2 February 2025, and general-purpose AI provisions from 2 August 2025. Transparency rules under Article 50 began applying on 2 August 2026, with specific transitional provisions.
Following the AI Omnibus, which the Commission reports entered into force on 27 July 2026, its timeline gives 2 December 2027 for Annex III high-risk rules and 2 August 2028 for high-risk systems embedded in regulated products covered by Annex I. These are category-specific dates, not a blanket postponement of all AI obligations.
The Commission says the previous company AI-literacy requirement has been simplified, with a stronger promotional role for the Commission and Member States. Do not treat older summaries of Article 4 as a current blanket training mandate. Check the amended law for your role and system; FAIRE recommends appropriate staff understanding and oversight as practical governance, not certification of compliance.
A note on legal advice
The AI Act is being applied through a developing regulatory framework, and the implications can differ by system, provider, deployer and use case. This article is general information and does not constitute legal advice or a compliance assessment.